EXECUTIVE SUMMARY:
Seven years since its discovery, the Ngioweb botnet remains a significant cybersecurity challenge, primarily targeting residential IoT devices such as routers, cameras, and vacuums. Originally identified in 2017, Ngioweb functions as a proxy network used for malicious purposes, including anonymizing illicit activities. Recent findings indicate that its operators, leveraging an extensive arsenal of exploits, scan, and compromise vulnerable devices, selling them as residential proxies through platforms like Nsocks. The botnet has grown exponentially, increasing from 3,000 daily IPs in 2020 to a staggering 30,000 IPs in 2024. Nsocks markets these infected devices globally for under $1.50 for 24-hour access, providing anonymity through cryptocurrency payments. This continued exploitation highlights the persistent vulnerability of IoT devices, and the sophisticated methods employed by Ngioweb operators to evade detection and maintain their infrastructure.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
Seven years since its discovery, the Ngioweb botnet remains a significant cybersecurity challenge, primarily targeting residential IoT devices such as routers, cameras, and vacuums. Originally identified in 2017, Ngioweb functions as a proxy network used for malicious purposes, including anonymizing illicit activities. Recent findings indicate that its operators, leveraging an extensive arsenal of exploits, scan, and compromise vulnerable devices, selling them as residential proxies through platforms like Nsocks. The botnet has grown exponentially, increasing from 3,000 daily IPs in 2020 to a staggering 30,000 IPs in 2024. Nsocks markets these infected devices globally for under $1.50 for 24-hour access, providing anonymity through cryptocurrency payments. This continued exploitation highlights the persistent vulnerability of IoT devices, and the sophisticated methods employed by Ngioweb operators to evade detection and maintain their infrastructure.[emaillocker id="1283"]
The Ngioweb botnet employs advanced techniques, including domain generation algorithms (DGA) and encrypted command-and-control (C&C) communications, to avoid detection and enhance its resilience. Recent investigations revealed that its scanning activity targets specific vulnerabilities in Linear eMerge, Zyxel routers, and other devices. For instance, CVE-2019-7256 allows command injection on Linear eMerge systems, enabling attackers to deploy payloads tailored to various CPU architectures. The botnet's C&C communications incorporate encrypted TXT records as authenticity checks, complicating interception efforts. Moreover, changes to the filenames used in communications, such as “request.js” or “piwik.js,” demonstrate attempts to bypass existing detection signatures. Infected devices serve as proxies, with data exfiltrated, including system IDs and architecture, before activation. Platforms like Nsocks commercialize these systems, offering proxy services categorized by ISP, region, and device type, emphasizing the global scale of this operation.
The Ngioweb botnet exemplifies the persistent threat posed by unpatched IoT vulnerabilities, with its operators refining their tools and techniques to sustain their network. By exploiting weaknesses in widely used devices, the botnet has established itself as a robust and profitable enterprise. Its evolution, from basic proxy functions to leveraging residential devices globally, underscores the need for stringent IoT security measures and proactive monitoring. The commercialization of infected systems through platforms like Nsocks highlights the integration of cybercrime into illicit markets. Organizations and individuals must prioritize securing IoT devices to mitigate risks posed by botnets like Ngioweb. This enduring threat serves as a reminder of the ongoing challenges in combating cybercrime and securing the expanding IoT landscape.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Initial Access | T1189 | Drive-by Compromise |
| T1190 | Exploit Public-Facing Application | |
| Persistence | T1543 | Create or Modify System Process |
| Defense Evasion | T1140 | Deobfuscate/Decode Files or Information |
| T1497 | Virtualization/Sandbox Evasion | |
| T1222 | File and Directory Permissions Modification | |
| T1562 | Impair Defenses | |
| Discovery | T1082 | System Information Discovery |
| Command and Control | T1090 | Proxy |
| Impact | T1496 | Resource Hijacking |
REFERENCES:
The following reports contain further technical details:
https://levelblue.com/blogs/labs-research/ngioweb-remains-active-7-years-later